Kyber, a multi-chain decentralized finance (DeFi) platform, discovered a vulnerability to its website code that allowed exploiters to run away with approximately $265,000.
Two “whale” addresses appeared to be impacted by the attack, according to Kyber, which <a href="https://twitter.com/KyberNetwork/status/1565421311073038336?s=20&t=CQl2AqvRpwlOCQMv_sPdqQ">plans to</a> reimburse the losses. Kyber said it discovered the exploit, which let attackers insert a “false approval, allowing a hacker to transfer a user’s funds to his address,” on Sept. 1 and “neutralized” the threat within two hours.
The exploit hit KyberSwap, a decentralized exchange that allows users to swap between currencies on different blockchains. KyberSwap’s blockchain contracts were not affected. The problem stemmed from malicious Google Tag Manager code in the KyberSwap website, according to a <a href="https://t.co/3qDRccZKPs">statement</a> from Kyber.
“We strongly urge all #DeFi projects to conduct a thorough check on your frontend code & associated Google Tag Manager (GTM) scripts as the attacker may have targeted multiple sites,” Kyber <a href="https://twitter.com/KyberNetwork/status/1565421317003784192?s=20&t=CQl2AqvRpwlOCQMv_sPdqQ">tweeted</a>.
The attack on Kyber was relatively small in comparison with other <a href="https://www.coindesk.com/business/2022/07/27/defi-has-become-crypto-crimes-main-arena-crystal-blockchain-says/">recent attacks</a> on DeFi projects, which have seen numerous multimillion-dollar thefts of users’ funds. However, it once again highlights the wide range of ways DeFi users are vulnerable to attacks.
<i><b>Read more: </b></i><a href="https://www.coindesk.com/business/2022/07/27/defi-has-become-crypto-crimes-main-arena-crystal-blockchain-says/" target="_blank"><i><b>DeFi Has Become Crypto Crime’s Main Arena, Crystal Blockchain Says</b></i></a>